TLS Certificate Verification Bypass in Lemur by Netflix
CVE-2026-44305

6.8MEDIUM

Key Information:

Vendor

Netflix

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44305?

Lemur, a tool for managing TLS certificates, was found to have a vulnerability in its LDAP authentication module. Versions prior to 1.9.0 did not enforce TLS certificate verification effectively when LDAP TLS was enabled, potentially allowing man-in-the-middle attackers to capture sensitive authentication credentials. This issue highlights the importance of properly configuring certificate verification to safeguard against interception. The vulnerability was resolved in version 1.9.0, and users are encouraged to update to this version for enhanced security.

Affected Version(s)

lemur < 1.9.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.